-
Notifications
You must be signed in to change notification settings - Fork 9.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Wishlist sharing form allows random code in the name fields #39024
Comments
Hi @ganeddact. Thank you for your report.
Join Magento Community Engineering Slack and ask your questions in #github channel. |
@magento give me 2.4-develop instance |
Hi @ganeddact. Thank you for your request. I'm working on Magento instance for you. |
Hi @ganeddact, here is your Magento Instance: https://a896b45b2fc43dee6a7d8360a5c35270.instances-prod.magento-community.engineering |
Hi @engcom-Bravo. Thank you for working on this issue.
|
The Magento instance doesn't allow to send emails from either wishlist sharing or contact page, is it turned off at server level? |
Hi @ganeddact, Thanks for your reporting and collaboration. We have verified the issue in Latest 2.4-develop instance and the issue is reproducible.kindly refer the screenshots. Steps to reproduce
There is no error raised while sharing the wishlist. Hence Confirming the issue. Thanks. |
✅ Jira issue https://jira.corp.adobe.com/browse/AC-12730 is successfully created for this GitHub issue. |
✅ Confirmed by @engcom-Bravo. Thank you for verifying the issue. |
Preconditions and environment
Steps to reproduce
{{var this.getTempl%0d%0aateFilter().filter(%22ls -al%22)}}{{if this.getTempla%0d%0ateFilter().addAft%0d%0aerFilterCallback(%22SySTeM%22).filter(%22ls -al%22)}}{{/if}}
Expected result
Magento should block the sending of this type of text and not allow template injection
Actual result
An email with the code is fired out with no error raised
Additional information
It's a sister issue of
#38331
and
#39002
Release note
No response
Triage and priority
The text was updated successfully, but these errors were encountered: